PT-2016-7576 · Nvidia · Nvidia Windows Gpu Display Driver

Oliver Chang

·

Published

2016-11-08

·

Updated

2019-03-07

·

CVE-2016-8807

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA Windows GPU Display Driver versions prior to 342.00 for R340 and prior to 375.63 for R375
Description The issue concerns a vulnerability in the kernel mode layer handler for DxgDdiEscape ID 0x10000e9, where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a stack buffer overflow. This can lead to denial of service or potential escalation of privileges.
Recommendations For NVIDIA Windows GPU Display Driver versions prior to 342.00 for R340, update to version 342.00 or later. For NVIDIA Windows GPU Display Driver versions prior to 375.63 for R375, update to version 375.63 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8807

Affected Products

Nvidia Windows Gpu Display Driver